@infosechandbookRegarding your recommendation to skip legacy headers, is there any downside to sending these headers aside from just sending extra bytes?

My worry is that some 'strange' browsers — the ones included in smart TVs and ereaders and other edge cases — have bolted on support for TLS 1.2 but have less modern behaviour in other aspects of how they render a page.